Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit.Fileless.MTGen


  • This topic is locked This topic is locked
11 replies to this topic

#1 micheloh62

micheloh62

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 28 July 2017 - 11:18 AM

I ran MalwareBytes and found Rootkit.Fileless.MTGen and quarantined. I am running on WIN 7 Pro machine. Can I follow instructions from this response from a year ago to remove?
 
https://www.bleepingcomputer.com/forums/t/615887/malwarebytes-found-rootkitfilelessmtgen-is-it-removed/
 
Presenting problems which may or may not be related:
-After installing a new cable modem my spouse cannot get onto his intranet at work as before (VPN)
-IS person at his place of employment says our IP address is Blacklisted
-His computer is MAC/mine is PC running WIN 7 Pro
Mod Edit:  Merged posts, moved topic to MRL forum - Hamluis.
Here is FRST scan:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2017
Ran by Owner (administrator) on HP-PC (28-07-2017 12:23:26)
Running from C:\Users\Owner\Downloads
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseHardwareService.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe
(ArcSoft, Inc.) C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Articulate Global, Inc.) C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe
(Articulate Global, Inc.) C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Citrix Online, a division of Citrix Systems, Inc.) C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\4732\g2mstart.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\SMART Product Drivers\SMARTInk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTTrayIcon.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\DesktopMenu.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe
(Citrix Online, a division of Citrix Systems, Inc.) C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\4732\g2mcomm.exe
(Flexera Software LLC) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(Citrix Online, a division of Citrix Systems, Inc.) C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\4732\g2mlauncher.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseSoftwareService.exe
(Joyent, Inc) C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\SBWDKService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\SMART Product Drivers\Office\SMARTInk-SBSDKProxy.exe
(Joyent, Inc) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseConnectorService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\SMART Product Drivers\SMARTInkPrivilegedAccess.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [763520 2012-08-07] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-07] (Qualcomm Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2887440 2012-03-08] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2016-03-30] (IDT, Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [Articulate 360 Desktop Service] => C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe [205576 2017-03-06] (Articulate Global, Inc.)
HKLM\...\Run: [Articulate 360 Desktop Application] => C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe [448776 2017-03-06] (Articulate Global, Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-03-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation)
HKLM-x32\...\Run: [DTRun] => C:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [517456 2010-11-24] (ArcSoft Inc.)
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184704 2012-03-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SMART Ink] => C:\Program Files (x86)\SMART Technologies\SMART Product Drivers\SMARTInk.exe [285600 2016-08-07] (SMART Technologies)
HKLM-x32\...\Run: [SMART Floating Tools] => C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe [9024304 2013-11-20] (SMART Technologies ULC)
HKLM-x32\...\Run: [SMARTNotification] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe [204592 2014-02-12] (SMART Technologies)
HKLM-x32\...\Run: [SMART Tray Tools] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTTrayIcon.exe [744752 2014-02-12] (SMART Technologies)
HKLM-x32\...\Run: [SMART Board Service] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe [1933616 2014-02-12] (SMART Technologies)
HKLM-x32\...\Run: [sbsdk-server] => C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\NodeLauncher.exe [62768 2013-08-22] (SMART Technologies)
HKLM-x32\...\Run: [Response Desktop Menu] => C:\Program Files (x86)\SMART Technologies\Education Software\DesktopMenu.exe [1312560 2013-11-20] (SMART Technologies ULC)
HKLM-x32\...\Run: [ResponseConnectorService] => C:\Program Files (x86)\SMART Technologies\Education Software\response-connector-server\NodeLauncher.exe [40448 2013-11-20] (SMART Technologies)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe [23153352 2017-07-20] (Microsoft Corporation)
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\...\Run: [GoToMeeting] => C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\4732\g2mstart.exe [41536 2016-04-03] (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google)
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\...\Run: [Google Update] => C:\Users\Owner\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-27] (Google Inc.)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-08-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 64.233.222.2 64.233.222.7
Tcpip\..\Interfaces\{32EF1DD6-EF15-4786-9C80-51352F8AA9CF}: [DhcpNameServer] 64.233.222.2 64.233.222.7
Tcpip\..\Interfaces\{5EC68A38-3A57-4A33-AED5-275BE21AA8DF}: [DhcpNameServer] 64.233.222.2 64.233.222.7

Internet Explorer:
==================
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-07-20] (Microsoft Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-07] (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-07-20] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-20] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-07-20] (Microsoft Corporation)
BHO-x32: SMART Notebook Download Utility -> {67BCF957-85FC-4036-8DC4-D4D80E00A77B} -> C:\Program Files (x86)\SMART Technologies\Education Software\NotebookPlugin.dll [2013-11-27] (SMART Technologies ULC.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-07-20] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-07-20] (Microsoft Corporation)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/US/Core/Player/2020PlayerAX_IKEA_Win32.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-20] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-20] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-20] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-20] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 6n2zxcq9.default
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\6n2zxcq9.default [2017-07-28]
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\6n2zxcq9.default -> Bing
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: (DigitalPersona Extension) - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2016-03-30] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-15] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-15] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-07-20] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-07-20] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\.DEFAULT: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll [2012-07-20] (Digital Persona, Inc.)
FF Plugin HKU\S-1-5-21-821098437-3889027770-4098322766-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Owner\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-04-02] (Citrix Online)
FF Plugin HKU\S-1-5-21-821098437-3889027770-4098322766-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-821098437-3889027770-4098322766-1000: @talk.google.com/O1DPlugin -> C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-821098437-3889027770-4098322766-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-821098437-3889027770-4098322766-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Owner\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Owner\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2012-07-20]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211072 2012-08-07] (Qualcomm Atheros Commnucations) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3705536 2017-07-03] (Microsoft Corporation)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [494456 2012-07-20] (DigitalPersona, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321896 2017-07-06] (HP Inc.)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165144 2012-03-28] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1719040 2016-08-10] (PDF Complete Inc)
R2 Response Hardware; C:\Program Files (x86)\SMART Technologies\Education Software\ResponseHardwareService.exe [20272 2013-11-20] (SMART Technologies ULC)
R2 SMARTHelperService; C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe [538416 2014-02-12] (SMART Technologies)
R2 uArcCapture; C:\Windows\SysWow64\ArcVCapRender\uArcCapture.exe [498352 2012-04-05] (ArcSoft, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-03-28] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-07] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.)
R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [42816 2012-02-03] (ArcSoft, Inc.)
R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2012-08-07] (Qualcomm Atheros)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [188352 2017-07-28] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [101784 2017-07-28] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [45472 2017-07-28] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253856 2017-07-28] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-07-28] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKsl657c9fdc; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8E10A135-8096-4D8E-9890-2C79537DDB17}\MpKsl657c9fdc.sys [44928 2017-07-27] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 SMARTMouseFilterx64; C:\Windows\System32\DRIVERS\SMARTMouseFilterx64.sys [10240 2014-02-12] (SMART Technologies)
R3 SMARTVHidMiniVistaAmd64; C:\Windows\System32\DRIVERS\SMARTVHidMiniVistaAmd64.sys [9216 2014-02-12] (SMART Technologies)
S3 SMARTVTabletPCx64; C:\Windows\System32\DRIVERS\SMARTVTabletPCx64.sys [22184 2014-02-12] (SMART Technologies ULC)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [2621128 2015-07-16] (Sonix Tech. Co., Ltd.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-28 12:23 - 2017-07-28 12:24 - 00023518 _____ C:\Users\Owner\Downloads\FRST.txt
2017-07-28 12:23 - 2017-07-28 12:23 - 00000000 ____D C:\FRST
2017-07-28 12:21 - 2017-07-28 12:22 - 02381824 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2017-07-28 10:28 - 2017-07-28 11:31 - 00084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-07-28 10:28 - 2017-07-28 10:28 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-07-28 10:28 - 2017-07-28 10:28 - 00188352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-07-28 10:28 - 2017-07-28 10:28 - 00101784 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-07-28 10:28 - 2017-07-28 10:28 - 00045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-07-28 10:28 - 2017-07-28 10:28 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-28 10:28 - 2017-07-28 10:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-28 10:27 - 2017-07-28 10:27 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-07-28 10:27 - 2017-07-28 10:27 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-28 10:27 - 2017-06-27 12:06 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-07-28 10:26 - 2017-07-28 10:27 - 65033984 _____ (Malwarebytes ) C:\Users\Owner\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-07-28 10:14 - 2017-07-28 10:48 - 00001078 _____ C:\Windows\system32dbgraw.bmp
2017-07-25 12:49 - 2017-07-25 12:49 - 00215658 _____ C:\Users\Owner\Downloads\letter_to_fbi_re_ivanka_sf86.pdf
2017-07-15 12:54 - 2017-07-15 12:54 - 05824512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2017-07-11 18:44 - 2017-06-29 22:57 - 02319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-07-11 18:44 - 2017-06-29 22:57 - 02058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-07-11 18:44 - 2017-06-29 22:39 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-11 18:44 - 2017-06-29 22:38 - 01363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-07-11 18:44 - 2017-06-29 02:27 - 25734656 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-07-11 18:44 - 2017-06-29 02:02 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-07-11 18:44 - 2017-06-29 01:44 - 05975552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-07-11 18:44 - 2017-06-29 01:23 - 20270592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-07-11 18:44 - 2017-06-29 01:23 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-11 18:44 - 2017-06-29 00:58 - 15253504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-07-11 18:44 - 2017-06-29 00:52 - 04549632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-07-11 18:44 - 2017-06-29 00:43 - 13663744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-07-11 18:44 - 2017-06-29 00:41 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-07-11 18:44 - 2017-06-29 00:24 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-07-11 18:44 - 2017-06-22 10:58 - 03223040 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-07-11 18:44 - 2017-06-12 18:49 - 00731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-07-11 18:44 - 2017-06-12 18:28 - 00554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-11 18:44 - 2017-06-09 11:33 - 01680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-07-11 18:44 - 2017-06-06 11:30 - 01867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-07-11 18:44 - 2017-05-16 11:35 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-07-11 18:44 - 2017-05-03 11:34 - 00094952 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-07-11 18:44 - 2017-05-03 11:29 - 01206272 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 01555968 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 00620544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 00535552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 00311296 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-07-11 18:44 - 2017-05-03 09:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-07-11 18:44 - 2017-03-22 22:06 - 01691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-07-11 18:43 - 2017-07-06 00:56 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2017-07-11 18:43 - 2017-06-30 00:15 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-07-11 18:43 - 2017-06-29 23:32 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-07-11 18:43 - 2017-06-29 22:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-07-11 18:43 - 2017-06-29 22:40 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-07-11 18:43 - 2017-06-29 22:40 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-07-11 18:43 - 2017-06-29 22:39 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-07-11 18:43 - 2017-06-29 22:38 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-11 18:43 - 2017-06-29 22:38 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-07-11 18:43 - 2017-06-29 22:38 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-07-11 18:43 - 2017-06-29 22:38 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-07-11 18:43 - 2017-06-29 22:38 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-07-11 18:43 - 2017-06-29 22:38 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-07-11 18:43 - 2017-06-29 22:38 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-07-11 18:43 - 2017-06-29 22:27 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-07-11 18:43 - 2017-06-29 22:27 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-07-11 18:43 - 2017-06-29 22:26 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-07-11 18:43 - 2017-06-29 22:26 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-07-11 18:43 - 2017-06-29 02:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-07-11 18:43 - 2017-06-29 02:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-07-11 18:43 - 2017-06-29 02:04 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-07-11 18:43 - 2017-06-29 02:03 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-07-11 18:43 - 2017-06-29 02:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-07-11 18:43 - 2017-06-29 02:02 - 02899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-07-11 18:43 - 2017-06-29 02:02 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-07-11 18:43 - 2017-06-29 01:55 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-07-11 18:43 - 2017-06-29 01:54 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-07-11 18:43 - 2017-06-29 01:51 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-07-11 18:43 - 2017-06-29 01:50 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-07-11 18:43 - 2017-06-29 01:50 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-07-11 18:43 - 2017-06-29 01:50 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-07-11 18:43 - 2017-06-29 01:50 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-07-11 18:43 - 2017-06-29 01:43 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-07-11 18:43 - 2017-06-29 01:39 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-07-11 18:43 - 2017-06-29 01:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-07-11 18:43 - 2017-06-29 01:31 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-07-11 18:43 - 2017-06-29 01:31 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-07-11 18:43 - 2017-06-29 01:30 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-07-11 18:43 - 2017-06-29 01:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-07-11 18:43 - 2017-06-29 01:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-07-11 18:43 - 2017-06-29 01:23 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-07-11 18:43 - 2017-06-29 01:23 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-07-11 18:43 - 2017-06-29 01:23 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-07-11 18:43 - 2017-06-29 01:22 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-07-11 18:43 - 2017-06-29 01:22 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-07-11 18:43 - 2017-06-29 01:22 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-07-11 18:43 - 2017-06-29 01:19 - 02290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-11 18:43 - 2017-06-29 01:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-07-11 18:43 - 2017-06-29 01:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-07-11 18:43 - 2017-06-29 01:14 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-07-11 18:43 - 2017-06-29 01:13 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-07-11 18:43 - 2017-06-29 01:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-07-11 18:43 - 2017-06-29 01:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-07-11 18:43 - 2017-06-29 01:11 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-07-11 18:43 - 2017-06-29 01:09 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-07-11 18:43 - 2017-06-29 01:09 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-07-11 18:43 - 2017-06-29 01:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-07-11 18:43 - 2017-06-29 01:07 - 02132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-07-11 18:43 - 2017-06-29 01:05 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-07-11 18:43 - 2017-06-29 01:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-07-11 18:43 - 2017-06-29 01:00 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-07-11 18:43 - 2017-06-29 01:00 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-07-11 18:43 - 2017-06-29 00:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-07-11 18:43 - 2017-06-29 00:56 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-07-11 18:43 - 2017-06-29 00:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-07-11 18:43 - 2017-06-29 00:54 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-07-11 18:43 - 2017-06-29 00:53 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-07-11 18:43 - 2017-06-29 00:48 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-07-11 18:43 - 2017-06-29 00:47 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-07-11 18:43 - 2017-06-29 00:46 - 02057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-07-11 18:43 - 2017-06-29 00:46 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-07-11 18:43 - 2017-06-29 00:29 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-07-11 18:43 - 2017-06-29 00:28 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-11 18:43 - 2017-06-29 00:23 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-07-11 18:43 - 2017-06-15 16:23 - 00753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-07-11 18:43 - 2017-06-12 18:54 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-07-11 18:43 - 2017-06-12 18:54 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-07-11 18:43 - 2017-06-12 18:54 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-07-11 18:43 - 2017-06-12 18:49 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 01363456 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2017-07-11 18:43 - 2017-06-12 18:49 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-07-11 18:43 - 2017-06-12 18:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 01227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2017-07-11 18:43 - 2017-06-12 18:29 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-07-11 18:43 - 2017-06-12 18:29 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-07-11 18:43 - 2017-06-12 18:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-07-11 18:43 - 2017-06-12 18:19 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-07-11 18:43 - 2017-06-12 18:14 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-07-11 18:43 - 2017-06-12 18:14 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2017-07-11 18:43 - 2017-06-12 18:14 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe
2017-07-11 18:43 - 2017-06-12 18:12 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-07-11 18:43 - 2017-06-12 18:12 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-07-11 18:43 - 2017-06-12 18:12 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-07-11 18:43 - 2017-06-12 18:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-07-11 18:43 - 2017-06-12 18:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-07-11 18:43 - 2017-06-12 18:06 - 00303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-07-11 18:43 - 2017-06-12 18:06 - 00157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2017-07-11 18:43 - 2017-06-12 18:06 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe
2017-07-11 18:43 - 2017-06-12 18:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-07-11 18:43 - 2017-06-10 11:59 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-07-11 18:43 - 2017-06-10 11:39 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-07-11 18:43 - 2017-06-06 11:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-07-11 18:43 - 2017-05-30 00:56 - 01895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-07-11 18:43 - 2017-05-30 00:56 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-07-11 18:43 - 2017-05-30 00:56 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-07-11 18:43 - 2017-05-21 00:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-07-11 18:43 - 2017-05-21 00:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-07-11 18:43 - 2017-05-16 11:35 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-07-11 18:43 - 2017-05-16 11:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-07-10 13:27 - 2017-07-10 13:27 - 00211554 _____ C:\Users\Owner\Documents\Application - New Albany Aide.pdf
2017-07-03 11:13 - 2017-07-03 11:13 - 00000000 ____D C:\Users\Owner\AppData\Local\Hewlett-Packard_Developme

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-28 10:41 - 2017-04-03 12:10 - 00000000 ____D C:\Users\Owner\AppData\Local\Deployment
2017-07-28 10:41 - 2016-04-22 22:40 - 00000000 ____D C:\Users\Owner\AppData\Local\6e4fc
2017-07-28 10:27 - 2017-01-16 16:56 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForOwner
2017-07-28 10:27 - 2017-01-16 16:56 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForOwner.job
2017-07-28 10:26 - 2009-07-14 00:45 - 00027760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-07-28 10:26 - 2009-07-14 00:45 - 00027760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-07-28 10:18 - 2016-11-20 17:21 - 00000000 ____D C:\Users\Owner\AppData\LocalLow\Mozilla
2017-07-28 10:14 - 2016-08-07 12:10 - 00000000 ____D C:\Users\Public\Documents\Job Search
2017-07-28 10:14 - 2016-06-27 13:19 - 00000000 ____D C:\Users\Owner\Documents\Resume
2017-07-27 20:12 - 2016-03-28 10:21 - 00000000 ____D C:\ProgramData\PDFC
2017-07-27 14:03 - 2016-10-26 19:06 - 00000000 ____D C:\Users\Owner\Documents\SMART Notebook
2017-07-27 13:57 - 2016-10-26 18:13 - 00000000 ____D C:\Users\Owner\AppData\Roaming\SMART Technologies
2017-07-20 08:51 - 2016-03-30 18:51 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-07-20 08:50 - 2016-03-30 18:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-07-20 08:30 - 2016-11-19 17:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-07-20 08:30 - 2016-08-07 12:08 - 00000000 ____D C:\Users\Owner\Desktop\PDFs
2017-07-20 08:30 - 2016-04-23 13:25 - 00000000 ___RD C:\Users\Owner\Google Drive
2017-07-20 08:30 - 2016-03-30 09:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-07-19 17:00 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2017-07-19 16:30 - 2009-07-14 01:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-19 16:30 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2017-07-19 16:20 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-19 16:20 - 2009-07-14 00:45 - 00500080 _____ C:\Windows\system32\FNTCACHE.DAT
2017-07-19 16:18 - 2016-03-28 15:32 - 00000000 ____D C:\Windows\system32\appraiser
2017-07-18 19:23 - 2016-03-28 14:56 - 00000000 ____D C:\Windows\system32\MRT
2017-07-18 19:21 - 2016-03-28 14:56 - 135225752 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-07-18 19:17 - 2016-06-28 20:29 - 00010414 _____ C:\Users\Owner\Desktop\Volvo Search.xlsx
2017-07-18 09:11 - 2016-05-12 16:40 - 00000000 ____D C:\Users\Owner\Documents\Bluetooth Folder
2017-07-15 12:54 - 2016-10-26 18:13 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-07-15 12:54 - 2016-08-17 11:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-07-15 12:54 - 2016-03-28 10:19 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-07-15 12:54 - 2016-03-28 10:19 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-15 12:54 - 2016-03-28 10:19 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-07-10 13:27 - 2016-03-28 10:30 - 00000000 ____D C:\Users\Owner\AppData\Local\PDFC

Some files in TEMP:
====================
2016-03-30 16:47 - 2016-03-30 16:47 - 0059392 _____ (Intel Corporation) C:\Users\Owner\AppData\Local\Temp\AtpTimerInfo.dll
2016-03-28 10:06 - 2012-02-27 19:28 - 0525792 ____R (Microsoft Corporation) C:\Users\Owner\AppData\Local\Temp\DIFxAPI.dll
2016-03-30 09:12 - 2008-10-15 12:42 - 0050432 _____ () C:\Users\Owner\AppData\Local\Temp\Extract.exe
2016-07-12 20:03 - 2016-07-12 20:03 - 19527360 _____ (Adobe Systems Incorporated) C:\Users\Owner\AppData\Local\Temp\InstallAX_22_0_0_210.exe
2016-01-07 22:28 - 2016-01-07 22:28 - 42771288 _____ (Hewlett Packard                                             ) C:\Users\Owner\AppData\Local\Temp\SP57475.exe
2016-01-08 22:00 - 2016-01-08 22:00 - 8259600 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP59118.exe
2016-01-07 22:35 - 2016-01-07 22:35 - 7406272 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP59202.exe
2016-01-08 23:01 - 2016-01-08 23:01 - 3991232 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP61040.exe
2016-01-08 15:47 - 2016-01-08 15:47 - 96677456 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP61411.exe
2016-01-08 12:51 - 2016-01-08 12:51 - 65812504 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP62370.exe
2016-01-07 22:36 - 2016-01-07 22:36 - 6791024 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP63637.exe
2016-01-08 15:02 - 2016-01-08 15:02 - 58528008 _____ (Hewlett-Packard                                             ) C:\Users\Owner\AppData\Local\Temp\SP64641.exe
2016-01-08 13:13 - 2016-01-08 13:13 - 133164312 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP64676.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-07-22 15:49

==================== End of FRST.txt ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-07-2017
Ran by Owner (28-07-2017 12:25:13)
Running from C:\Users\Owner\Downloads
Windows 7 Professional Service Pack 1 (X64) (2016-03-28 13:43:33)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-821098437-3889027770-4098322766-500 - Administrator - Disabled)
Guest (S-1-5-21-821098437-3889027770-4098322766-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-821098437-3889027770-4098322766-1004 - Limited - Enabled)
Owner (S-1-5-21-821098437-3889027770-4098322766-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 26 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 26.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.137 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{8642397F-CF08-6B30-A477-A039BBAA511E}) (Version: 3.0.868.0 - Advanced Micro Devices, Inc.)
ArcSoft TotalMedia (HKLM-x32\...\{B3B67519-2201-4C38-8002-D54473D651F9}) (Version: 1.0.61.25 - ArcSoft) Hidden
ArcSoft TotalMedia (HKLM-x32\...\ArcSoft TotalMedia) (Version: 2.0.39.42 - ArcSoft)
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.39 - ArcSoft)
Articulate 360 (HKLM-x32\...\{439F3FAD-7AF0-4039-AA47-64BD0E0EE27A}) (Version: 1.4.10330.0 - Articulate Global, Inc.) Hidden
Articulate 360 (HKLM-x32\...\{b7d12c69-ec03-402f-8f42-bdd904fa2035}) (Version: 1.4.10330.0 - Articulate Global, Inc.)
Articulate Storyline 360 (HKLM-x32\...\{e26e2843-5cb7-42c4-a9d2-f1d9257c6d41}) (Version: 3.4.10364.0 - Articulate Global, Inc.)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Citrix Online Launcher (HKLM-x32\...\{09DA5EE2-7E46-4DC4-96F9-BFEE50D40659}) (Version: 1.0.408 - Citrix)
Evernote v. 4.5.4 (HKLM-x32\...\{550BFF6E-7376-11E1-99EA-984BE15F174E}) (Version: 4.5.4.6487 - Evernote Corp.)
Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
GoToMeeting 7.22.0.5506 (HKU\S-1-5-21-821098437-3889027770-4098322766-1000\...\GoToMeeting) (Version: 7.22.0.5506 - CitrixOnline)
Hewlett-Packard ACLM.NET v1.1.2.0 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard) Hidden
HP 3D DriveGuard (HKLM\...\{5B4F3B85-83F0-4BBF-9052-7A38B6B09634}) (Version: 5.0.8.0 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\...\{22706ADC-74A1-43A0-ABAE-47F84966B909}) (Version: 4.2.50.1 - Hewlett-Packard Company)
HP ESU for Microsoft Windows 7 (HKLM-x32\...\{240B2BF7-E7E6-425C-A2A4-A3149189BF7F}) (Version: 2.3.1 - Hewlett-Packard Company)
HP HD Webcam Driver (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1106.1_WHQL - Sonix)
HP ProtectTools Security Manager (HKLM\...\HPProtectTools) (Version: 7.0.2.1213 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{78E2C850-ADA6-420D-BA35-2F4A9BE733CC}) (Version: 8.4.19.3 - HP)
HP Support Solutions Framework (HKLM-x32\...\{CE7447C2-EF12-4EF3-BE51-BFC3B049C0F6}) (Version: 12.7.27.15 - HP)
HP System Default Settings (HKLM-x32\...\{3A61A282-4F08-4D43-920C-DC30ECE528E8}) (Version: 2.6.1 - Hewlett-Packard Company)
HP Wallpaper (HKLM-x32\...\{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}) (Version: 3.0.0.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6402.0 - IDT)
Intel® Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3090 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.76.1 - JMicron Technology Corp.)
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (Português do Brasil) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1046) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.7766.2096 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-821098437-3889027770-4098322766-1000\...\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.7766.2096 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.7766.2096 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.7766.2096 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.7668.2066 - Microsoft Corporation) Hidden
PDF Complete Corporate Edition (HKLM-x32\...\PDF Complete) (Version: 4.1.50 - PDF Complete, Inc)
PX Profile Update (HKLM-x32\...\{89FC4558-3689-C109-772E-3A6D5B96F019}) (Version: 1.00.1. - AMD) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.206 - Qualcomm Atheros Communications)
Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.58.411.2012 - Realtek)
ShellExtensionx64 (HKLM\...\{C7B984BF-44A8-43E7-9896-5C1CE80FA082}) (Version: 3.4.10364.0 - Articulate Global, Inc.) Hidden
SMART Common Files (HKLM-x32\...\{26A95DBF-A866-4838-A8C9-FA219FCBD22E}) (Version: 11.5.159.0 - SMART Technologies ULC)
SMART Gallery Essentials (HKLM-x32\...\{351556FA-F071-4A3C-8A21-818830C9DD46}) (Version: 1.0.19.0 - SMART Technologies ULC)
SMART Ink (HKLM-x32\...\{7AB1FDF1-6998-43AD-B705-EA8AF7439407}) (Version: 4.1.635.0 - SMART Technologies ULC)
SMART Lesson Activity Toolkit (HKLM-x32\...\{F4380B38-D62F-4D58-AA1D-C420C4E86049}) (Version: 1.0.19.0 - SMART Technologies ULC)
SMART Notebook (HKLM-x32\...\{79660EE7-9C0B-4962-B566-2693FE34719D}) (Version: 11.4.564.0 - SMART Technologies ULC)
SMART Product Drivers (HKLM-x32\...\{53330A17-78DE-458E-9997-292A2D6D3ADD}) (Version: 11.4.872.1 - SMART Technologies ULC)
SMART Response Software (HKLM-x32\...\{351B2133-C2A9-40A6-B6E8-B8468BD91D1A}) (Version: 4.8.497.0 - SMART Technologies ULC)
Storyline 360 (HKLM-x32\...\{A44AA0EA-6BE5-42C7-BBF0-4B61160B51E2}) (Version: 3.4.10364.0 - Articulate Global, Inc.) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.0.3.0 - Synaptics Incorporated)
Validity Fingerprint Sensor Driver (HKLM\...\{ADAA7361-54B8-4FC8-804E-94EC6C11ED68}) (Version: 4.5.133.0 - Validity Sensors, Inc.)
WinZip 15.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240CF}) (Version: 15.0.10039 - WinZip Computing, S.L. )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\4732\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ContextMenuHandlers1: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\Program Files (x86)\Bluetooth Suite\BtvAppExt.dll [2012-08-07] (Qualcomm Atheros Commnucations)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-09] (WinZip Computing, S.L.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => C:\Program Files (x86)\Bluetooth Suite\ShellContextExt.dll [2012-08-07] (Qualcomm Atheros Commnucations)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-09] (WinZip Computing, S.L.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2012-03-29] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-03-26] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-09] (WinZip Computing, S.L.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {03326032-2D8E-4A14-B289-517574AF571D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-821098437-3889027770-4098322766-1000UA => C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2016-12-16] (Google Inc.)
Task: {0FE5CF3D-AE40-435B-B7ED-735255ABAD8F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-07-03] (Microsoft Corporation)
Task: {28122A4E-7C57-4D36-9A9F-87422E0ED58B} - System32\Tasks\HPCeeScheduleForOwner => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-01-22] (Hewlett-Packard)
Task: {29DC2D62-9FBE-4C9B-A597-738ADEDBCA0A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-07-20] (Microsoft Corporation)
Task: {6D21DB0C-CD0C-4D75-A9AB-64F6B94933A7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-821098437-3889027770-4098322766-1000Core => C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2016-12-16] (Google Inc.)
Task: {7E2B582F-9BD8-456C-83AE-AE42872FC769} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-23] (Google Inc.)
Task: {805A4C30-7BC2-4544-AD60-8516A42DE553} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-07-03] (Microsoft Corporation)
Task: {895130F0-006C-44BC-965E-71906E0454E9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {938A2167-7974-499E-9480-E88A2EC1ADF4} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {94E246AB-D83E-4B21-AC30-2BC3D7D98BED} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-07-20] (Microsoft Corporation)
Task: {996230CB-3F29-4700-8159-9ACFB0AF3216} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {9B5F979C-4783-40CC-B741-3D970116CD20} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-07-15] (Adobe Systems Incorporated)
Task: {A9935754-865C-4E79-B75F-D972A50D72F1} - System32\Tasks\G2MUpdateTask-S-1-5-21-821098437-3889027770-4098322766-1000 => C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\5530\g2mupdate.exe [2016-09-03] ()
Task: {BAE6AC04-8DB0-4937-9A8E-10E70A1052FD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-07-20] (Microsoft Corporation)
Task: {BFFAD85F-1147-4445-AF9F-E53F42EED98F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {DC926276-F98A-4EC7-9ECB-AE5B4C24BBF9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {E44B3742-DB32-4CEF-961F-AB4EEB0AC06B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-06-28] (HP Inc.)
Task: {E9E6C574-3F4B-4EE7-8A0D-183B9686B2CD} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {EE26CC0C-8300-4A2B-9F95-4E64C635AA7E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-23] (Google Inc.)
Task: {EF5FFECD-7B77-4D62-B655-4EE2313A9698} - System32\Tasks\G2MUploadTask-S-1-5-21-821098437-3889027770-4098322766-1000 => C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\5530\g2mupload.exe [2016-09-03] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-821098437-3889027770-4098322766-1000.job =>
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-821098437-3889027770-4098322766-1000.job =>
Task: C:\Windows\Tasks\HPCeeScheduleForOwner.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2012-01-17 16:57 - 2012-01-17 16:57 - 00298368 _____ () C:\Program Files\Hewlett-Packard\Pre-Boot Security for HP ProtectTools\BIOSDomainPlugin.dll
2011-10-12 02:03 - 2011-10-12 02:03 - 00213328 _____ () C:\Windows\system32\PassThroughOTP.dll
2016-03-28 10:05 - 2012-03-28 13:38 - 00128280 ____R () C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
2016-06-07 19:05 - 2016-06-07 19:05 - 00959168 _____ () C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-05-25 21:02 - 2017-01-29 09:55 - 08930504 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2016-03-28 10:00 - 2012-03-26 08:33 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-08-07 18:15 - 2012-08-07 18:15 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
2011-12-26 13:20 - 2011-12-26 13:20 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2012-03-29 23:07 - 2012-03-29 23:07 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2017-07-28 10:27 - 2017-06-27 12:06 - 02260432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-04-03 13:44 - 2017-04-03 13:44 - 02364840 _____ () C:\Windows\WinSxS\x86_smarttech.xqilla.vc100.1.1_9ca15c999435ee05_1.0.1.0_none_1bed397492abdaf4\xqilla-vc100-1_0.dll
2017-04-03 13:41 - 2017-04-03 13:41 - 00066976 _____ () C:\Windows\WinSxS\x86_smarttech.zlib.vc100.1.2_9ca15c999435ee05_1.0.1.0_none_a9eddec61c291613\zlib1-vc100-mt-1.2.dll
2016-10-26 18:11 - 2016-10-26 18:11 - 02310056 _____ () C:\Windows\WinSxS\x86_smarttech.redland.vc100.1.0_9ca15c999435ee05_1.0.1.0_none_abdcef110f80cf28\redland-vc100-1_0_9.dll
2017-04-03 13:41 - 2017-04-03 13:41 - 00051120 _____ () C:\Windows\WinSxS\x86_smarttech.boost_date_time.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_50d6b3902c95d15a\boost_date_time-vc100-mt-1_44.dll
2017-04-03 13:40 - 2017-04-03 13:40 - 00145328 _____ () C:\Windows\WinSxS\x86_smarttech.boost_filesystem.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_73736a4543634e09\boost_filesystem-vc100-mt-1_44.dll
2017-04-03 13:41 - 2017-04-03 13:41 - 00022440 _____ () C:\Windows\WinSxS\x86_smarttech.boost_system.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_3b5a2197c9e04a1f\boost_system-vc100-mt-1_44.dll
2017-04-03 13:41 - 2017-04-03 13:41 - 00054184 _____ () C:\Windows\WinSxS\x86_smarttech.boost_thread.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_472b4edec4bf8550\boost_thread-vc100-mt-1_44.dll
2017-04-03 13:41 - 2017-04-03 13:41 - 00053680 _____ () C:\Windows\WinSxS\x86_smarttech.boost_signals.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_8ce60f5e6bc42419\boost_signals-vc100-mt-1_44.dll
2017-04-03 13:41 - 2017-04-03 13:41 - 00524712 _____ () C:\Windows\WinSxS\x86_smarttech.boost_regex.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_cae4ebd2526cf46f\boost_regex-vc100-mt-1_44.dll
2017-05-14 10:00 - 2017-05-14 10:00 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\823fb789f2ad94c2ce33a6a11f82d7ea\IsdiInterop.ni.dll
2016-03-28 10:05 - 2012-02-01 21:25 - 00059904 ____R () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2016-03-28 10:05 - 2012-03-28 13:18 - 01198872 ____R () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
2016-10-26 18:07 - 2016-10-26 18:07 - 00633496 _____ () C:\Windows\WinSxS\x86_smarttech.boost.vc120.1.56_e7e76aadd9f46776_1.0.1.0_none_cacd116f976dee85\boost_regex-vc120-mt-1_56.dll
2016-10-26 18:07 - 2016-10-26 18:07 - 00087704 _____ () C:\Windows\WinSxS\x86_smarttech.boost.vc120.1.56_e7e76aadd9f46776_1.0.1.0_none_cacd116f976dee85\boost_thread-vc120-mt-1_56.dll
2016-10-26 18:07 - 2016-10-26 18:07 - 00022168 _____ () C:\Windows\WinSxS\x86_smarttech.boost.vc120.1.56_e7e76aadd9f46776_1.0.1.0_none_cacd116f976dee85\boost_system-vc120-mt-1_56.dll
2016-10-26 18:07 - 2016-10-26 18:07 - 00030872 _____ () C:\Windows\WinSxS\x86_smarttech.boost.vc120.1.56_e7e76aadd9f46776_1.0.1.0_none_cacd116f976dee85\boost_chrono-vc120-mt-1_56.dll
2016-10-26 18:07 - 2016-10-26 18:07 - 00045720 _____ () C:\Windows\WinSxS\x86_smarttech.boost.vc120.1.56_e7e76aadd9f46776_1.0.1.0_none_cacd116f976dee85\boost_date_time-vc120-mt-1_56.dll
2017-04-03 13:40 - 2017-04-03 13:40 - 01492840 _____ () C:\Windows\WinSxS\x86_smarttech.activation2.vc100.1.0_397ba524434296e4_1.0.6.0_none_071e22fe720f73fd\activation2-vc100-mt-s-x86.dll
2016-10-26 18:11 - 2016-10-26 18:11 - 01030048 _____ () C:\Windows\WinSxS\x86_smarttech.js.vc70.1.8_37a8c5fef6a21868_1.0.2.1_none_e909cd048128eadf\js32.dll
2013-11-27 15:50 - 2013-11-27 15:50 - 00460800 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\ziparchive-vc100-3_1_1a.dll
2013-08-22 19:43 - 2013-08-22 19:43 - 00272688 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SBSDK.node
2013-08-22 19:44 - 2013-08-22 19:44 - 00039216 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\HWR.node
2013-08-22 19:44 - 2013-08-22 19:44 - 00053040 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SWR.node
2013-08-22 19:44 - 2013-08-22 19:44 - 00057648 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\MWR.node
2013-08-22 19:44 - 2013-08-22 19:44 - 00014848 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SessionNotification.node
2011-04-08 09:57 - 2011-04-08 09:57 - 00514570 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00098816 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32api.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00110080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pywintypes27.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00364544 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pythoncom27.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00320512 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32com.shell.shell.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00914432 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_hashlib.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 01176576 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._core_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00806400 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._gdi_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00816128 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._windows_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 01067008 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._controls_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00733184 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._misc_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00682496 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pysqlite2._sqlite.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00088064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ctypes.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00686080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\unicodedata.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00119808 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32file.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00108544 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32security.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00007168 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\hashobjs_ext.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00017920 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\thumbnails_ext.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00088064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\usb_ext.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00012800 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\common.time34.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00018432 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32event.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00167936 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32gui.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00046080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_socket.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 01303552 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ssl.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00128512 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_elementtree.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00127488 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pyexpat.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00038912 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32inet.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00036864 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_psutil_windows.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00524248 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\windows._lib_cacheinvalidation.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00011264 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32crypt.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00123392 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._wizard.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00077312 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._html2.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00027648 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_multiprocessing.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00020480 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_yappi.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00035840 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32process.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00078848 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._animate.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00024064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pipe.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00010240 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\select.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00025600 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pdh.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00017408 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32profile.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00022528 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32ts.pyd
2013-11-20 22:18 - 2013-11-20 22:18 - 00068400 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\ResponseAddon.node
2013-11-20 22:18 - 2013-11-20 22:18 - 00077616 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\ClickerAddon.node
2016-03-30 18:50 - 2016-03-30 18:52 - 01754296 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\tmpod.dll
2016-05-25 21:01 - 2017-01-29 16:18 - 00039624 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconvpxy.dll
2016-06-07 19:05 - 2016-06-07 19:05 - 00679624 _____ () C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-05-25 21:02 - 2017-01-29 05:46 - 08929992 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-821098437-3889027770-4098322766-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 64.233.222.2 - 64.233.222.7
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{E2158BD0-E328-4B29-ABFD-BBA0A409A482}] => (Allow) C:\Program Files (x86)\Bluetooth Suite\Btvstack.exe
FirewallRules: [{2DA74B63-6B27-4A24-9955-30B98E9E8CA9}] => (Allow) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
FirewallRules: [{6429DE24-44DA-41AE-8A5A-B6A1F18AC7A1}] => (Allow) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
FirewallRules: [{6DFDBDE9-D1FA-49EE-B982-D02561D452BF}] => (Allow) C:\Program Files (x86)\Bluetooth Suite\Win7Ui.exe
FirewallRules: [{77976B0C-6B4A-4136-BE33-A2DC760E8A94}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FE0C6054-F825-4418-A573-F745E68E3408}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{CDB2BD8A-3DC1-43DC-B810-D337B3899285}C:\program files (x86)\bluetooth suite\bttray.exe] => (Allow) C:\program files (x86)\bluetooth suite\bttray.exe
FirewallRules: [UDP Query User{AD44C24C-C7A7-479E-9342-ABFEFA94CCDB}C:\program files (x86)\bluetooth suite\bttray.exe] => (Allow) C:\program files (x86)\bluetooth suite\bttray.exe
FirewallRules: [TCP Query User{347413FC-35DA-4AB6-ADF5-B67897331925}C:\program files (x86)\bluetooth suite\btvstack.exe] => (Allow) C:\program files (x86)\bluetooth suite\btvstack.exe
FirewallRules: [UDP Query User{64FBC190-6E04-41C9-AD61-5CBB2B0EE601}C:\program files (x86)\bluetooth suite\btvstack.exe] => (Allow) C:\program files (x86)\bluetooth suite\btvstack.exe
FirewallRules: [{EAC33518-5196-440B-BC3E-DB07ED9D9865}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{C9D21780-A6D5-42E6-9E9F-941CAAD364A6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{AAA6EBAE-C973-480A-B5D2-DAAE0A749A97}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\UCGui.exe
FirewallRules: [{699B902E-C0BC-4FBB-A802-E8DC184FB544}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\UCGui.exe
FirewallRules: [{B2AACB4B-E990-4647-8C17-71A1F9ADC6B9}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\UCService.exe
FirewallRules: [{DF963011-1EF5-4153-BFAD-223D6DB1F33F}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\UCService.exe
FirewallRules: [{45D6253C-65E3-4C76-BAA9-4F6435C89584}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTSNMPAgent.exe
FirewallRules: [{C1B513B4-7986-4C41-8A41-AEDF81E5F691}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTSNMPAgent.exe
FirewallRules: [{CCE56CFD-94C8-4533-A1C0-B6643DE6C584}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseSoftwareService.exe
FirewallRules: [{DB7EA120-6EEC-45B6-9145-59D65B893309}] => (Allow) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseSoftwareService.exe
FirewallRules: [{6632D471-D1C6-4707-BA1C-35B51B4B8F12}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{54785D6C-E016-4017-B81C-E33C611486CF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{9624EF8E-09F4-447D-9CC2-4ED081E03C0F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe

==================== Restore Points =========================

14-07-2017 12:14:47 Windows Update
18-07-2017 09:20:26 Windows Update
18-07-2017 19:18:32 Windows Update
22-07-2017 11:51:36 Windows Update
25-07-2017 12:34:45 Windows Update

==================== Faulty Device Manager Devices =============

Name: SMART Virtual TabletPC
Description: SMART Virtual TabletPC
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: SMART Technologies ULC
Service: SMARTVTabletPCx64
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/28/2017 10:28:00 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/28/2017 10:28:00 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/28/2017 10:17:45 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/28/2017 10:15:26 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/28/2017 10:15:26 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/27/2017 01:24:43 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/26/2017 09:38:31 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/25/2017 12:27:10 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/24/2017 11:49:23 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (07/23/2017 07:08:50 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (07/23/2017 07:26:57 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 117.2.0.0

    Update Source: Microsoft Malware Protection Center

    Update Stage: Search

    Source Path: http://go.microsoft.com/fwlink/?LinkID=260974&clcid=0x409&NRI=true&arch=x64&eng=2.1.13804.0&sig=117.2.0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

    Signature Type: Network Inspection System

    Update Type: Full

    User: NT AUTHORITY\NETWORK SERVICE

    Current Engine Version:

    Previous Engine Version: 2.1.13804.0

    Error code: 0x80072ee2

    Error description: The operation timed out

Error: (07/23/2017 07:06:01 PM) (Source: Microsoft Antimalware) (EventID: 3002) (User: )
Description: Microsoft Antimalware Real-Time Protection feature has encountered an error and failed.

    Feature: On Access

    Error Code: 0x80004005

    Error description: Unspecified error

    Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.

Error: (07/19/2017 04:21:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PDF Document Manager service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (07/19/2017 04:21:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the PDF Document Manager service to connect.

Error: (07/19/2017 04:16:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (07/19/2017 04:16:18 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the HP Service service to connect.

Error: (07/18/2017 09:11:53 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {C2BFE331-6739-4270-86C9-493D9A04CD38} did not register with DCOM within the required timeout.

Error: (07/18/2017 09:11:27 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.

Error: (07/18/2017 09:09:37 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {1A1F4206-0688-4E7F-BE03-D82EC69DF9A5} did not register with DCOM within the required timeout.

Error: (07/17/2017 11:52:54 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {C332C124-340D-4430-AA0D-C75602876FCC} did not register with DCOM within the required timeout.


==================== Memory info ===========================

Processor: Intel® Core™ i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 50%
Total physical RAM: 8071.49 MB
Available physical RAM: 4011.92 MB
Total Virtual: 16141.16 MB
Available Virtual: 11257.18 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:929.41 GB) (Free:825.88 GB) NTFS
Drive f: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F02B2EF1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=929.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=2 GB) - (Type=0C)

==================== End of Addition.txt ============================

Edited by hamluis, 28 July 2017 - 01:23 PM.


BC AdBot (Login to Remove)

 


#2 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 28 July 2017 - 11:53 AM

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 7/28/17
Scan Time: 10:29 AM
Log File: Malwarebytes 7.28.17.txt
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2457
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: HP-PC\Owner

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330971
Threats Detected: 5
Threats Quarantined: 5
Time Elapsed: 7 min, 49 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 1
Rootkit.Fileless.MTGen, HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\21949\SHELL\OPEN\COMMAND, Quarantined, [1317], [261829],1.0.2457

Registry Value: 1
Rootkit.Fileless.MTGen, HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\21949\SHELL\OPEN\COMMAND|, Quarantined, [1317], [261829],1.0.2457

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 3
Rootkit.Fileless.MTGen, C:\USERS\OWNER\APPDATA\LOCAL\6E4FC\E76E4.BAT, Quarantined, [1317], [327457],1.0.2457
Rootkit.Fileless.MTGen, C:\USERS\OWNER\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\5DAD6.LNK, Quarantined, [1317], [-1],0.0.0
Rootkit.Fileless.MTGen, C:\USERS\OWNER\START MENU\PROGRAMS\STARTUP\5DAD6.LNK, Quarantined, [1317], [-1],0.0.0

Physical Sector: 0
(No malicious items detected)


(end)



#3 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,761 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:08:42 AM

Posted 28 July 2017 - 07:56 PM

Welcome. :)

  • Highlight the entire content of the quote box below.

Start::  
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Restriction <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
2016-03-30 16:47 - 2016-03-30 16:47 - 0059392 _____ (Intel Corporation) C:\Users\Owner\AppData\Local\Temp\AtpTimerInfo.dll
2016-03-28 10:06 - 2012-02-27 19:28 - 0525792 ____R (Microsoft Corporation) C:\Users\Owner\AppData\Local\Temp\DIFxAPI.dll
2016-03-30 09:12 - 2008-10-15 12:42 - 0050432 _____ () C:\Users\Owner\AppData\Local\Temp\Extract.exe
2016-07-12 20:03 - 2016-07-12 20:03 - 19527360 _____ (Adobe Systems Incorporated) C:\Users\Owner\AppData\Local\Temp\InstallAX_22_0_0_210.exe
2016-01-07 22:28 - 2016-01-07 22:28 - 42771288 _____ (Hewlett Packard                                             ) C:\Users\Owner\AppData\Local\Temp\SP57475.exe
2016-01-08 22:00 - 2016-01-08 22:00 - 8259600 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP59118.exe
2016-01-07 22:35 - 2016-01-07 22:35 - 7406272 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP59202.exe
2016-01-08 23:01 - 2016-01-08 23:01 - 3991232 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP61040.exe
2016-01-08 15:47 - 2016-01-08 15:47 - 96677456 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP61411.exe
2016-01-08 12:51 - 2016-01-08 12:51 - 65812504 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP62370.exe
2016-01-07 22:36 - 2016-01-07 22:36 - 6791024 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP63637.exe
2016-01-08 15:02 - 2016-01-08 15:02 - 58528008 _____ (Hewlett-Packard                                             ) C:\Users\Owner\AppData\Local\Temp\SP64641.exe
2016-01-08 13:13 - 2016-01-08 13:13 - 133164312 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP64676.exe
2017-07-20 08:29 - 2017-07-20 08:29 - 00098816 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32api.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00110080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pywintypes27.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00364544 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pythoncom27.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00320512 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32com.shell.shell.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00914432 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_hashlib.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 01176576 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._core_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00806400 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._gdi_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00816128 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._windows_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 01067008 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._controls_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00733184 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._misc_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00682496 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pysqlite2._sqlite.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00088064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ctypes.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00686080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\unicodedata.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00119808 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32file.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00108544 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32security.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00007168 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\hashobjs_ext.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00017920 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\thumbnails_ext.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00088064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\usb_ext.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00012800 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\common.time34.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00018432 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32event.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00167936 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32gui.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00046080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_socket.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 01303552 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ssl.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00128512 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_elementtree.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00127488 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pyexpat.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00038912 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32inet.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00036864 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_psutil_windows.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00524248 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\windows._lib_cacheinvalidation.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00011264 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32crypt.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00123392 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._wizard.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00077312 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._html2.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00027648 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_multiprocessing.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00020480 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_yappi.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00035840 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32process.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00078848 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._animate.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00024064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pipe.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00010240 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\select.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00025600 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pdh.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00017408 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32profile.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00022528 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32ts.pyd
C:\Users\Owner\AppData\Local\Temp\_MEI53002
HOSTS:
Removeproxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset C:\resettcpip.txt
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
CMD: Bitsadmin /Reset /Allusers
EMPTYTEMP:
Reboot:
End::

  • Right click on the highlighted text and select Copy.
  • Start FRST (FRST64) with Administrator privileges
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

Please download Junkware Removal Tool to your Desktop.

  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.

Download AdwCleaner from here. Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8/10 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

65MBhLLb.png


  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be moved to Quarantine.
  • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this

adwcleaner_delete_restart.jpg


  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt

 


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#4 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 29 July 2017 - 08:57 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 29-07-2017
Ran by Owner (28-07-2017 21:58:11) Run:1
Running from C:\Users\Owner\Downloads
Loaded Profiles: Owner (Available Profiles: Owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
 
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Restriction <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Owner\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
2016-03-30 16:47 - 2016-03-30 16:47 - 0059392 _____ (Intel Corporation) C:\Users\Owner\AppData\Local\Temp\AtpTimerInfo.dll
2016-03-28 10:06 - 2012-02-27 19:28 - 0525792 ____R (Microsoft Corporation) C:\Users\Owner\AppData\Local\Temp\DIFxAPI.dll
2016-03-30 09:12 - 2008-10-15 12:42 - 0050432 _____ () C:\Users\Owner\AppData\Local\Temp\Extract.exe
2016-07-12 20:03 - 2016-07-12 20:03 - 19527360 _____ (Adobe Systems Incorporated) C:\Users\Owner\AppData\Local\Temp\InstallAX_22_0_0_210.exe
2016-01-07 22:28 - 2016-01-07 22:28 - 42771288 _____ (Hewlett Packard                                             ) C:\Users\Owner\AppData\Local\Temp\SP57475.exe
2016-01-08 22:00 - 2016-01-08 22:00 - 8259600 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP59118.exe
2016-01-07 22:35 - 2016-01-07 22:35 - 7406272 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP59202.exe
2016-01-08 23:01 - 2016-01-08 23:01 - 3991232 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP61040.exe
2016-01-08 15:47 - 2016-01-08 15:47 - 96677456 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP61411.exe
2016-01-08 12:51 - 2016-01-08 12:51 - 65812504 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP62370.exe
2016-01-07 22:36 - 2016-01-07 22:36 - 6791024 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP63637.exe
2016-01-08 15:02 - 2016-01-08 15:02 - 58528008 _____ (Hewlett-Packard                                             ) C:\Users\Owner\AppData\Local\Temp\SP64641.exe
2016-01-08 13:13 - 2016-01-08 13:13 - 133164312 _____ (Hewlett-Packard Company                                     ) C:\Users\Owner\AppData\Local\Temp\SP64676.exe
2017-07-20 08:29 - 2017-07-20 08:29 - 00098816 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32api.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00110080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pywintypes27.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00364544 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pythoncom27.dll
2017-07-20 08:29 - 2017-07-20 08:29 - 00320512 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32com.shell.shell.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00914432 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_hashlib.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 01176576 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._core_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00806400 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._gdi_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00816128 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._windows_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 01067008 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._controls_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00733184 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._misc_.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00682496 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pysqlite2._sqlite.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00088064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ctypes.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00686080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\unicodedata.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00119808 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32file.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00108544 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32security.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00007168 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\hashobjs_ext.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00017920 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\thumbnails_ext.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00088064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\usb_ext.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00012800 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\common.time34.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00018432 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32event.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00167936 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32gui.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00046080 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_socket.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 01303552 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ssl.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00128512 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_elementtree.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00127488 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\pyexpat.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00038912 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32inet.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00036864 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_psutil_windows.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00524248 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\windows._lib_cacheinvalidation.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00011264 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32crypt.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00123392 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._wizard.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00077312 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._html2.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00027648 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_multiprocessing.pyd
2017-07-20 08:28 - 2017-07-20 08:28 - 00020480 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\_yappi.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00035840 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32process.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00078848 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._animate.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00024064 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pipe.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00010240 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\select.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00025600 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pdh.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00017408 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32profile.pyd
2017-07-20 08:29 - 2017-07-20 08:29 - 00022528 ____R () C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32ts.pyd
C:\Users\Owner\AppData\Local\Temp\_MEI53002
HOSTS:
Removeproxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset C:\resettcpip.txt
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
CMD: Bitsadmin /Reset /Allusers
EMPTYTEMP:
Reboot:

*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04} => key removed successfully
HKU\S-1-5-21-821098437-3889027770-4098322766-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA} => key removed successfully
C:\Users\Owner\AppData\Local\Temp\AtpTimerInfo.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\DIFxAPI.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\Extract.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\InstallAX_22_0_0_210.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP57475.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP59118.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP59202.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP61040.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP61411.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP62370.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP63637.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP64641.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\SP64676.exe => moved successfully
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32api.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\pywintypes27.dll" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\pythoncom27.dll" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32com.shell.shell.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_hashlib.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._core_.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._gdi_.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._windows_.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._controls_.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._misc_.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\pysqlite2._sqlite.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ctypes.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\unicodedata.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32file.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32security.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\hashobjs_ext.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\thumbnails_ext.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\usb_ext.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\common.time34.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32event.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32gui.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_socket.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_ssl.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_elementtree.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\pyexpat.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32inet.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_psutil_windows.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\windows._lib_cacheinvalidation.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32crypt.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._wizard.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._html2.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_multiprocessing.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\_yappi.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32process.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\wx._animate.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pipe.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\select.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32pdh.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32profile.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002\win32ts.pyd" => not found.
"C:\Users\Owner\AppData\Local\Temp\_MEI53002" => not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-821098437-3889027770-4098322766-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========


========= netsh advfirewall reset =========

Ok.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Ok.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= netsh int ip reset C:\resettcpip.txt =========

Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========

Failed to clear log AirSpaceChannel. The requested operation cannot be performed over an enabled direct channel. The channel must first be disabled before performing the requested operation.

========= End of CMD: =========


========= Bitsadmin /Reset /Allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 75022793 B
Java, Flash, Steam htmlcache => 39421 B
Windows/system/drivers => 9449583304 B
Edge => 0 B
Chrome => 0 B
Firefox => 407462537 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 66228 B
systemprofile32 => 66356 B
LocalService => 0 B
NetworkService => 13215284 B
Owner => 931783252 B

RecycleBin => 13533478102 B
EmptyTemp: => 22.7 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 22:14:15 ====



#5 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 29 July 2017 - 09:00 AM

After running FRST64 and restart I got message that Windows Firewall blocked Qualcomm Atheros Comm. and the option to allow access or cancel. Which should I choose?



#6 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 29 July 2017 - 09:10 AM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Professional x64
Ran by Owner (Administrator) on Sat 07/29/2017 at 10:03:01.68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 8

Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1YJLPPTS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FTF8S0L8 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JLHF0YJ4 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MVF1XXZW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1YJLPPTS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FTF8S0L8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JLHF0YJ4 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MVF1XXZW (Temporary Internet Files Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 07/29/2017 at 10:04:45.14
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#7 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 29 July 2017 - 09:15 AM

# AdwCleaner 7.0.0.0 - Logfile created on Sat Jul 29 14:14:23 2017
# Updated on 2017/17/07 by Malwarebytes
# Database: 07-16-2017.1
# Running on Windows 7 Professional (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########



#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,761 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:08:42 AM

Posted 29 July 2017 - 11:58 AM

After running FRST64 and restart I got message that Windows Firewall blocked Qualcomm Atheros Comm. and the option to allow access or cancel. Which should I choose?

According to its definition, Qualcomm Atheros is a developer of semiconductors for network communications, most noteably wireless chipsets for the IEEE 802.11 standard of wireless networking which are used by many wireless device manufacturers, including Netgear and D-Link. Atheros offers Bluetooth chips for a variety of platforms and offers integrated combo WLAN and Bluetooth chips. Their hybrid networking technology, Hy-Fi, integrates WLAN and Ethernet technologies which complies with the IEEE 1905.1 standard for hybrid home networking, is capable of detecting the optimal path for data to be transferred.

 

How is the computer doing?


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#9 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 29 July 2017 - 03:43 PM

Seems good. Latest Malwarebytes scan is clean.

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 7/29/17
Scan Time: 4:27 PM
Log File:
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2464
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: HP-PC\Owner

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 326059
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 8 min, 11 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)


(end)



#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,761 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:08:42 AM

Posted 30 July 2017 - 08:13 AM

Congratulations.

 

Remove quarantined items:

 

Please download DelFix by Xplode and save to your Desktop.

  • Double-click on delfix.exe to run the tool.
    Vista/Windows 7/8/10 users right-click and select Run As Administrator.
  • Put a check mark next to these items:
    - Remove disinfection tools
    - Create registry backup
    delfix.jpg
    .
  • Click the "Run" button.
  • When the tool has finished, it will create and open a log report (DelFix.txt)

 

 

Always keep an antivirus active and updated.

 

Best regards. :)


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 micheloh62

micheloh62
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:08:42 AM

Posted 30 July 2017 - 09:58 AM

Done. Thank you!



#12 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,761 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:08:42 AM

Posted 30 July 2017 - 01:26 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users